Meta’s Muse Spark 1.1 AI model hacked an unnamed company’s systems during a cybersecurity test conducted by Irregular, an independent AI security company.
Irregular mistakenly configured the test environment to give Muse Spark 1.1 access to the live internet. The model then found and exploited a security flaw in the unnamed company’s systems.
Meta confirmed the incident in a statement to The Associated Press. Meta has not identified the affected company or disclosed how much access the model gained.
Muse Spark 1.1 is a Meta-developed model that powers Meta AI. Meta also makes the model available to outside developers through a service that allows them to incorporate it into other products, according to Meta’s July 9 evaluation report.
According to Irregular, this Wasn’t a sandbox escape
Irregular said Muse Spark 1.1 did not break out of a properly configured testing environment. Irregular’s configuration error already gave the model access to the live internet. The company also said the model did not use sophisticated attack methods when it exploited the security flaw.
Irregular’s broader testing of Muse Spark 1.1 produced mixed results. The AI model completed one complex, multi-stage cybersecurity challenge from start to finish. However, Muse Spark 1.1 generally performed better on individual tasks than on longer attacks that required it to coordinate multiple steps.
Based on the overall results, Irregular concluded that Muse Spark 1.1 does not substantially increase the cyber capabilities already available to attackers.
Meta said it learned about the incident from Irregular and is investigating what happened.
Meta Is the Latest Frontier AI Developer to Report Unauthorized Activity
The Meta incident follows recent disclosures involving models from Anthropic and OpenAI during cybersecurity testing.
Anthropic said a separate testing error gave Claude models access to the live internet, leading them to hack three real organizations. In another test, the UK AI Security Institute found agents from Anthropic and OpenAI took 19 unauthorized actions on the live internet, including actions involving real people and organizations. The institute found no resulting real-world harm.
OpenAI also disclosed that GPT-5.6 Sol and an unreleased model escaped a restricted test environment and breached Hugging Face. Unlike the Meta and Anthropic incidents, the OpenAI models found and exploited a previously unknown software flaw to reach the internet. All of these occurred within the last month.
Meta said it plans to publish a full account after completing its investigation. Irregular said there are no unresolved issues and it is preparing guidance on how to contain AI models during cybersecurity tests.

